awesome-repositories.com
Blog
MCP
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektMCP-ServerÜber unsRanking-MethodikPresse
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

6 Repos

Awesome GitHub RepositoriesDetection Rules and Analytics

Repositories of detection logic, signatures, and analytic queries.

Explore 6 awesome GitHub repositories matching part of an awesome list · Detection Rules and Analytics. Refine with filters or upvote what's useful.

Awesome Detection Rules and Analytics GitHub Repositories

Finde die besten Repos mit KI.Wir suchen mit KI nach den am besten passenden Repositories.
  • sigmahq/sigmaAvatar von SigmaHQ

    SigmaHQ/sigma

    10,136Auf GitHub ansehen↗

    Sigma is a suite of tools for defining generic log signatures and translating them for multiple backends. It provides a structured way to define malicious behavior and detection logic independently of any specific backend technology, acting as a translation engine that maps generic event fields and correlation logic to the proprietary query languages of security data lakes and SIEM platforms. The project features a plugin-based multi-backend query generator that exports security detections into various database and log management formats. It also includes a threat framework mapping tool that

    Generic signature format for SIEM systems.

    Pythonelasticsearchidslogging
    Auf GitHub ansehen↗10,136
  • otrf/threathunter-playbookAvatar von OTRF

    OTRF/ThreatHunter-Playbook

    4,591Auf GitHub ansehen↗

    ThreatHunter-Playbook ist ein Framework für Threat-Hunting-Playbooks und ein Detection-Engineering-Workflow, das darauf ausgelegt ist, den Sicherheitserkennungs-Lebenszyklus zu standardisieren. Es fungiert als Community-getriebenes Repository für Angreifer-Methoden und Erkennungslogik und nutzt interaktive Notebooks, um technische Dokumentation mit ausführbaren Analysen zu kombinieren. Das Projekt bietet eine Validierungssuite zum Testen von Sicherheitshypothesen gegen vorab aufgezeichnete Telemetrie-Datensätze. Dies stellt sicher, dass die Erkennungslogik in lokalen oder Cloud-Umgebungen verifiziert wird, bevor sie in der Produktion eingesetzt wird. Das Framework deckt Sicherheits-Detection-Engineering, Threat-Hunting-Standardisierung und die Formalisierung der Hunt-Planung ab. Es nutzt strukturierte Vorlagen und komponentenbasierte Modellierung, um den Prozess von der ersten Hypothese bis zur endgültigen Validierung zu leiten.

    Community project for sharing detection logic and tradecraft.

    Pythondfirhunterhunting
    Auf GitHub ansehen↗4,591
  • elastic/detection-rulesAvatar von elastic

    elastic/detection-rules

    2,508Auf GitHub ansehen↗

    This project is a detection-as-code framework providing a library of security monitoring rules and predefined detection content for Elasticsearch data indices. It serves as a threat detection rule library designed to identify malicious activity and attack patterns across diverse data streams in cloud and on-premises environments. The framework implements a detection engineering workflow where rules are defined in YAML and managed as versioned code. It includes a set of command-line utilities for automated rule deployment, metadata searching, and template generation, supported by a Python-base

    Collection of detection rules for security monitoring.

    Pythonthreat-detectionthreat-hunting
    Auf GitHub ansehen↗2,508
  • chronicle/detection-rulesAvatar von chronicle

    chronicle/detection-rules

    502Auf GitHub ansehen↗

    This repository contains example YARA-L rules and dashboards for use within Google Security Operations (SecOps)

    YARA-L rules for cloud-based detection APIs.

    Python
    Auf GitHub ansehen↗502
  • googlecloudplatform/security-analyticsG

    GoogleCloudPlatform/security-analytics

    0Auf GitHub ansehen↗

    Community-driven audit and threat queries for cloud environments.

    Auf GitHub ansehen↗0
  • sublime-security/sublime-rulesS

    sublime-security/sublime-rules

    0Auf GitHub ansehen↗

    Detection and response rules for email threats.

    Auf GitHub ansehen↗0
  1. Home
  2. Part of an Awesome List
  3. Databases & Data
  4. Detection Rules and Analytics